Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.
History

Mon, 18 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell precision 5820 Tower
Dell precision 5820 Tower Firmware
Dell precision 7820 Tower
Dell precision 7820 Tower Firmware
Dell precision 7865 Tower
Dell precision 7865 Tower Firmware
Dell precision 7920 Tower
Dell precision 7920 Tower Firmware
CPEs cpe:2.3:h:dell:precision_5820_tower:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_7820_tower:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_7865_tower:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_7920_tower:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:precision_5820_tower_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:precision_7820_tower_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:precision_7865_tower_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:precision_7920_tower_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell precision 5820 Tower
Dell precision 5820 Tower Firmware
Dell precision 7820 Tower
Dell precision 7820 Tower Firmware
Dell precision 7865 Tower
Dell precision 7865 Tower Firmware
Dell precision 7920 Tower
Dell precision 7920 Tower Firmware

Thu, 10 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 02:15:00 +0000

Type Values Removed Values Added
Description Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.
Weaknesses CWE-1328
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2025-04-10T01:55:55.597Z

Updated: 2025-04-10T14:28:52.086Z

Reserved: 2025-03-13T05:03:56.323Z

Link: CVE-2025-29989

cve-icon Vulnrichment

Updated: 2025-04-10T14:28:44.948Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-10T02:15:30.680

Modified: 2025-08-18T12:42:51.290

Link: CVE-2025-29989

cve-icon Redhat

No data.